Vendor lock-in and your pod: what you'd still depend on us for

Adopting us today trades one kind of lock-in for another.

The half with genuinely low lock-in, and we did not build it

Solid solved storage and access control, and we built none of it.

  • Your files are files, addressed over HTTP, in open formats, in a server whose source anyone can read and run.
  • The specification is public and has more than one implementation. Leaving a pod provider is moving files between servers that speak the same protocol.
  • You can run the server yourself, in your own jurisdiction, with no dependency on us at all.

That is a real answer to the lock-in question, and the credit belongs to the Solid community. Our contribution on this page's good side is that we chose their server instead of writing our own.

The credential format, which is open with one asterisk

The credential shape we issue is a standard one, checkable by any conformant verifier rather than by a client only we can supply.

And the asterisk, which we are not going to bury: our own issuer metadata advertises a proof type that we defined ourselves. It is not a standard, and nothing outside our own software knows what to do with it. A format that is open except for the piece we invented is open with a qualification, and a buyer should price that qualification rather than hear "open standards" and move on.

What you would actually depend on us for

The identifier. did:solidus resolves against our chain, four validators, all operated by us. The method specification is public, so anyone could build a second resolver, and nobody has, including us. Generic DID tooling does not resolve it either. In specification your identifier is portable. In practice it points at our availability.

The registry. The accountability list that says which issuers are worth trusting is a single list we operate. There is no second operator and no federation. One list, one operator, us.

Every one of those is the same absence wearing a different hat, and it is the honest core of this page.

And a plain product gap: there is no bulk export

You can download a file. You can download a credential. You cannot take everything at once.

The same search style finds the upload feature in the file browser. The search works. There is no export feature to find.

For a technical reader this matters less than it looks, every resource is an HTTP GET, so a script is a short one. For everybody else it matters exactly as much as it sounds, and "the protocol makes it possible" is not a feature we shipped. And leaving does not remove your account, there is no deletion path for it.

The comparison we are not going to make

The defensible statement is narrower: the storage layer here has genuinely low switching cost, because it is a protocol rather than a product, and that property is Solid's. Everything we added on top has a switching cost we have not yet paid down.

Keep reading

Vendor lock-in and your pod: what you'd still depend on us for · Solidus